Certifications & Compliance

Every attestation we hold.
One page. Nothing buried.

Security questionnaires shouldn't require a discovery call. Below is the complete list of Flosum's certifications, audits, and framework alignments - what each one attests to, why it matters to you, and where the evidence lives. Audit reports and certificates are published in our documentation or available under NDA.

Book a Meeting  →

25–30%

higher renewal quotes customers are already seeing — with no cap on what comes next

Flat

Flosum pricing stays constant no matter how fast AI grows your data

100%

independent of Salesforce — the vendor holding your safety net stands apart from the platform
The Attestation Chain

Our SOC 2 Type II is ours. Our subprocessors bring their own.

A common vendor trick is pointing at a cloud provider's certifications as if they were the vendor's. We don't. Flosum holds its own SOC 2 Type II covering Flosum's controls, policies, and operations. Our subprocessors - Salesforce and AWS - maintain their own independently audited programs, and each layer can produce its own report.

Flosum - our own report

Flosum SOC 2 Type II

Covers Flosum's application, operations, personnel, and policies for both Cloud and Native products. Audited over a full period (Jan–Dec 2025), not a point in time. Available under NDA.

Subprocessor

Salesforce

Provides its own SOC and ISO reports covering the Salesforce platform, where our native managed package runs. Available at compliance.salesforce.com.

Subprocessor

AWS

Provides its own SOC and ISO reports covering the physical and virtualization infrastructure beneath Flosum-hosted Cloud Apps. Available via AWS Artifact.

Why a SOC 2 Type II specifically?

A Type I says the right controls existed on one day. A Type II says an independent auditor watched those controls operate over months and verified they actually worked - the right policies, followed in practice, validated externally over time. When you assess Flosum, ask every vendor in your stack for the same: their own Type II, not their cloud provider's.

Corporate-Level

Independently certified and audited

These attestations cover Flosum as an organization - its information security management, controls, and operations - validated by accredited third parties. Each card states what it is and why it should matter to your evaluation.

01
Audited · Type II

SOC 2 Type II

Trust Services Criteria - security, availability, processing integrity, confidentiality, and privacy - evaluated across a full audit period (Jan–Dec 2025), covering both Cloud and Native products.

Flosum's own report - not a subprocessor's
Why it matters

An external auditor verified our controls operated effectively over twelve months. Point-in-time attestations can be staged; a Type II period cannot.

02
Certified

ISO/IEC 27001

Information Security Management System. Independent certification that Flosum manages information security risk through structured policies, controls, and governance. Certificate published in our documentation.

Flosum's own report - not a subprocessor's
Why it matters

Proves security is run as a management system with executive ownership, risk assessment, and continuous improvement - not a collection of ad-hoc tools.

03
Certified

ISO/IEC 27017

Cloud-specific security controls: best practices and additional safeguards for protecting data in cloud services and multi-tenant environments.

Flosum's own report - not a subprocessor's
Why it matters

ISO 27001 alone predates modern cloud risk. 27017 adds the cloud-specific controls - tenant isolation, virtual machine hardening, shared-responsibility clarity.

04
Certified

ISO/IEC 27018

Protection of personally identifiable information (PII) in public clouds, with strict requirements for how personal data is stored and processed.

Flosum's own report - not a subprocessor's
Why it matters

Your Salesforce data is full of PII. This certifies the specific controls governing how PII is handled in cloud processing - a frequent gap in vendor programs.

05
Compliant

DoD IL4 / IL5*

U.S. Department of Defense impact-level requirements for controlled unclassified information (CUI). Salesforce-native deployments running in Salesforce Government Cloud environments can support workloads at higher impact levels, including IL5.*

Flosum's own report - not a subprocessor's
Why it matters

If you serve or sell to the DoD, your toolchain must match your data's impact level. Flosum's native architecture inherits the authorization of the government cloud it runs in.

06
Compliant

HIPAA

Safeguards for protected health information (PHI), supporting customer compliance with U.S. healthcare privacy and security regulations.

Flosum's own report - not a subprocessor's
Why it matters

DevOps and backup tooling touches production data - including PHI. A vendor without HIPAA safeguards makes your compliance officer's problem list longer, not shorter.

07
Aligned

NIST 800 Series

Controls and practices aligned with NIST federal cybersecurity guidance for threat detection, prevention, and response.

Flosum's own report - not a subprocessor's
Why it matters

NIST 800-53 is the control language of the U.S. federal government and most mature security programs. Alignment means your assessors can map our controls directly to yours.

08
Compliant

PCI Level 1

The highest standard for the secure processing and storage of payment card information.

Flosum's own report - not a subprocessor's
Why it matters

If cardholder data exists anywhere in your Salesforce org, every tool that can read, back up, or migrate that org is in scope. Level 1 is the strictest tier there is.

09
Compliant

GDPR & U.S. Data Privacy Framework

Adherence to EU and U.S. data-privacy regulation, giving customers control over personal information, consent, and cross-border transfer.

Flosum's own report - not a subprocessor's
Why it matters

Backup and migration tooling moves personal data by definition. GDPR/DPF adherence means lawful basis for transfer is our problem to document - not a gap you discover at renewal.

Product-Level

Evidence per product, not just per company

Corporate certifications tell you the organization is disciplined. Product-level evidence tells you the software you're deploying was tested. We publish both.

Static application security testing (Checkmarx)

Flosum DevOps undergoes Checkmarx static code analysis. Reports are published in the security section of our documentation.

Third-party penetration testing

Flosum Backup & Archive is penetration-tested by independent third parties; pentest reports are available in our documentation.

Salesforce AppExchange security review

The Salesforce-native managed package is distributed via AppExchange and subject to Salesforce's mandatory partner security review process.

Semi-annual third-party audits of hosted services

Flosum-hosted services are audited every six months by reputable third parties. The AWS environment is continuously evaluated against AWS security best practices and monitored with CloudTrail and related AWS services.

Product security & compliance statements

Published statements covering system architecture, APIs, network security, authentication, data management, logging, patch management, data protection, risk management, incident response and disaster recovery, secure SDLC, and vendor risk management.

Encryption, verifiable in the docs

AES-256 at rest, TLS 1.2+ only in transit (TLS 1.0/1.1 and SSL disabled), AWS KMS-protected keys with a unique key per connected org - documented publicly, not asserted privately.

Compliance × Architecture

How compliance maps to your deployment model

Certifications only mean something within their scope. Here is how scope works across Flosum's deployment architectures - stated plainly, because your auditors will ask.

Deployment model What Flosum's certifications cover What you inherit or retain
Salesforce
Native
Flosum's application code, secure development lifecycle, and the AppExchange security review. Flosum's own SOC 2 Type II covers Native products. You inherit the platform compliance of the Salesforce environment your org runs in - including Government Cloud impact-level authorizations for public-sector orgs. Salesforce provides its own audit reports as subprocessor.
Flosum-
Hosted Cloud
The full stack: application, hosting operations, encryption, monitoring, and personnel - under Flosum's own SOC 2 Type II, ISO 27001/27017/27018, with semi-annual third-party audits. AWS provides its own reports for the physical infrastructure. You retain responsibility for identity administration, user provisioning, and least-privilege configuration.
Customer-
Hosted
Flosum's software and secure development practices. Certifications do not extend to infrastructure Flosum does not operate. Your organization's own certifications and controls govern the VM, network, storage, keys, and operations. This is exactly why government and defense customers choose it - their accreditation, their boundary.

Why we publish the limits of our certifications

A compliance page that only lists logos is marketing. One that tells you where each attestation starts and stops is documentation. If a vendor won't state the boundary of their SOC 2 scope, that is your first security finding.

Need the actual reports?

ISO certificates, Flosum's SOC 2 Type II report, Checkmarx results, and pentest summaries are available in our documentation or under NDA. Subprocessor reports are available directly from Salesforce and AWS. Send your security questionnaire - we've answered harder ones.

Security & Compliance Docs
Certificates, audit summaries, statements
Talk to Us
Send your security questionnaire

Questions we hear from Own customers

We're mid-contract with Own. Do we have to wait it out?

No. Flosum buys out your remaining Own contract, so the switch can happen on your timeline — not your renewal date's.


Are we unprotected during the migration?

No. We run both systems side by side until you have fully switched, so you're covered every single day of the transition.


How is Flosum priced?

Flat and constant — a number you can put in a budget and hold, no matter how fast your data grows. No usage-based surprises at renewal.


Is Flosum ready for Agentforce-scale change?

Yes. Flosum is built exclusively for Salesforce and designed for machine-scale change — automated full and incremental backups with granular, point-in-time restore for both data and metadata.


What does the meeting actually cover?

Thirty minutes: we review your current renewal quote, show you a live recovery, and give you a flat Flosum number to compare. No obligation.